Power Consumption Pattern Analysis for Malicious Software Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for protecting portable devices from malicious software attacks, such as viruses and worms, are inefficient as they significantly increase power consumption and overload the microprocessor, reducing battery life and performance.

Innovation Solution

A system and method that detects malicious software by monitoring power consumption patterns, using sensors to compare electrical power usage with threshold values and detecting frequency signatures associated with known software attacks, alerting users or administrators without significantly increasing power drain or processor load.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional scanning techniques are used to detect malicious code, then detection capability is improved, but power consumption increases significantly

Engineering Contradiction:
Improvemalicious code detection capabilityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent replaces the mechanical/scanning-based detection system with an electrical field-based monitoring system. Instead of using microprocessors to scan and analyze code (mechanical/electronic processing), the invention uses sensors to detect electrical field changes and power consumption patterns caused by malicious code execution. This substitution enables detection without the high power consumption associated with active scanning and processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces electrical field sensors as an intermediary between the malicious code and the detection system. Rather than directly analyzing code or monitoring system state through high-power processing, the sensors detect indirect electrical field signatures and power consumption patterns that indicate malicious code presence. This intermediary approach allows passive detection with minimal power consumption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional scanning techniques are used to detect malicious code, then detection capability is improved, but microprocessor performance is reduced

Engineering Contradiction:
Improvemalicious code detection capabilityVSAvoidmicroprocessor performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the microprocessor-based scanning and analysis system with an electrical field sensing system. Instead of requiring the microprocessor to execute scanning algorithms and analyze code patterns (which reduces available performance for other tasks), the detection function is transferred to dedicated sensors that passively monitor electrical field changes without burdening the microprocessor.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent segments the detection function from the main microprocessor system. By using separate electrical field sensors dedicated solely to detection, the invention isolates the detection task from general-purpose processing. This segmentation allows the microprocessor to maintain full performance for application tasks while sensors handle detection independently.

Inventive Principle:
Principle #1Segmentation

3Duration of action of moving object

If battery life is extended by reducing power consumption, then device portability is improved, but malicious code detection capability is reduced

Engineering Contradiction:
Improvebattery lifeVSAvoidmalicious code detection capability
Core Design Contradiction:
Duration of action of moving objectVSReliability

Solution Approach 1:

The patent replaces high-power active scanning methods with low-power electrical field sensing. The sensors continuously monitor for malicious code through passive electrical field detection without requiring significant power, enabling both extended battery life and maintained detection capability simultaneously.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system employs periodic sampling of electrical field patterns and power consumption levels rather than continuous high-power scanning. This periodic monitoring approach maintains detection capability while significantly reducing average power consumption, thereby extending battery life without sacrificing security.

Inventive Principle:
Principle #19Periodic action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Effectively detects malicious software attacks with minimal power consumption and processor load, extending battery life and maintaining device performance while identifying the type of attack.

Implementation Method 1

a sensor (e.g., current sensing resistor) for detecting an amount of electrical power or current consumed by the device

Methodology Applied
Scientific EffectElectrical Resistance: Electrical Resistance

Data Source

PatentUS7877621B2Detecting software attacks by monitoring electric power consumption patterns
Publication Date: 2011.01.25 VIRGINIA TECH INTELLECTUAL PROPERTIES INC
  • US7877621B2 patent drawing
  • US7877621B2 patent drawing
  • US7877621B2 patent drawing

AI summary

Software attacks such as worms and viruses are detected in an electronic device by monitoring power consumption patterns. In a first embodiment, software attacks are detected by an increase in power consumption. The increased power consumption can be caused by increased network traffic, or by increased activity in the microprocessor. Monitoring power consumption is particularly effective for detecting DOS/flooding attacks when the electronic device is in an idle state. In a second embodiment, a power consumption signal is converted to the frequency domain (e.g., by fast Fourier transform). The highest amplitude frequencies are identified. Specific software attacks produce characteristic frequencies in the power consumption signal. Software attacks are therefore detected by matching the highest amplitude frequencies with frequencies associated with specific worms and viruses. Identification of a particular software attack typically requires matching of 3 or more of the highest amplitude frequencies, and, optionally, amplitude information.